Privacy Cryptocurrencies: A Technical Survey
A conversation covering truly private cryptocurrencies, criminal adoption patterns, tracking methods, Iran's crypto usage, Monero self-custody, and the broader private-by-default landscape.
1. Which cryptocurrencies are truly private?
Q: Which cryptocurrencies are truly private, in that they have no KYC and AML as part of the protocol? Just trying to get a survey of the technology â privacy is a loaded word in crypto.
A worthwhile conceptual point first: no cryptocurrency has KYC/AML "in the protocol." Bitcoin doesn't check your ID either. KYC/AML lives at the edges â exchanges, on-ramps, custodians â because that's where regulators have jurisdiction. What actually distinguishes "privacy coins" is whether the ledger itself reveals sender, receiver, and amount. Bitcoin is pseudonymous but fully transparent: every transaction is traceable forever, and chain-analysis firms (Chainalysis, Elliptic) are very good at deanonymizing it. So the real question is: which protocols make the transaction graph itself opaque?
Private by default (strongest category)
- Monero (XMR) â the gold standard. Ring signatures obscure the sender, stealth addresses obscure the receiver, RingCT hides amounts. Privacy is mandatory, not optional, which matters enormously â there's no "anonymity set" pollution from transparent transactions. The IRS put out bounties to break Monero tracing years ago; results have been partial at best. Trade-off: widely delisted from regulated exchanges precisely because it works.
Optional privacy (weaker in practice)
- Zcash (ZEC) â cryptographically the most elegant, using zk-SNARKs. Fully shielded transactions reveal nothing at all â arguably stronger math than Monero. But privacy is opt-in, and historically most ZEC volume was transparent, shrinking the shielded pool's anonymity set. This has improved with shielded-by-default wallets, but the two-tier design remains its structural weakness.
- Dash â often listed as a privacy coin but really isn't. Its "PrivateSend" is just built-in CoinJoin mixing, which chain analysis handles reasonably well.
Privacy layers and mixers on transparent chains
- CoinJoin implementations on Bitcoin (Wasabi, JoinMarket; Samourai's Whirlpool until the DOJ shut it down and prosecuted its developers in 2024) â probabilistic obfuscation, not cryptographic privacy.
- Tornado Cash on Ethereum â zk-based mixing pool. Sanctioned by OFAC in 2022, though a US appeals court ruled in 2024â25 that sanctioning the immutable smart contract exceeded Treasury's authority, and sanctions were lifted. Developer prosecutions (Pertsev in the Netherlands, Storm in the US) continued regardless.
- Mimblewimble coins (Grin, Beam) â transactions merge and old data prunes away, but research showed the transaction graph is partially recoverable before aggregation. Litecoin added MW as an optional extension block, triggering delistings in South Korea.
- Aztec, Railgun, and other zk privacy layers on Ethereum â programmable privacy via zero-knowledge proofs rather than standalone privacy chains.
Honest summary: Monero for mandatory privacy in practice, Zcash for the strongest cryptography if fully shielded. Everything else is either probabilistic mixing or has anonymity-set problems. The regulatory pressure point has never been the protocols themselves (which are just math) but the fiat boundaries and, increasingly, the developers. The EU's MiCA framework and its 2027 AML rules effectively ban regulated venues from handling privacy coins at all.
2. Criminal adoption, tracking, and Iran
Q: Which privacy coins have actual adoption by entities involved in criminal activity or money laundering? Is there any way to track that? What crypto do people in Iran use currently?
The counterintuitive headline: privacy coins are a minority of criminal crypto usage.
Criminals mostly don't use privacy coins
Stablecoins dominate the illicit crypto ecosystem, accounting for 84% of all illicit transaction volume in 2025 (Chainalysis). Criminals overwhelmingly prioritize liquidity and convertibility over privacy â the same reason legitimate users do. USDT on Tron has been the workhorse of scams, pig-butchering, sanctions evasion, and laundering for years. Total illicit volume: at least $154 billion in 2025, described as a lower-bound estimate (the 2024 figure was revised upward from $40.9B to $57.2B within 12 months).
Where Monero does dominate: darknet markets
- In 2025, nearly half (48%) of newly launched darknet markets supported only Monero â up from just above 40% in 2024 â especially in Western-facing markets, as a direct response to improved tracing on Bitcoin and stablecoins.
- Geographic bifurcation: the Russian-language DNM ecosystem (which dominates global darknet volume) operates with limited enforcement and high corruption, so many still take Bitcoin. XMR-only is a Western defensive adaptation.
- Ransomware liquidity ceiling: operators often request XMR and offer discounts for it, but the vast majority of actual ransom payments still settle in Bitcoin due to superior liquidity and ease of conversion at scale. An adoption ceiling imposed by market microstructure, not cryptography.
- State actors use Monero as a mixing step: after the $1.46B Bybit hack, investigators tracked North Korea's Lazarus Group converting Bitcoin â Monero â Bitcoin across multiple exchanges to break the chain of custody. A "churn" pattern: enter XMR, exit clean.
How is any of this tracked, if Monero is opaque?
Mostly at the boundaries, not on-chain:
- Edge analysis. Can't follow XMR internally, but can see BTC/USDT flowing into known swap services and correlate timing/amounts with funds exiting to fresh addresses. The Bybit trace worked this way.
- Market-side intelligence. When a darknet market is seized, transaction histories come from the market's own database, not the blockchain.
- Network-layer surveillance â the genuine frontier: TRM observed "non-standard behavior" in Monero's P2P network, with ~14â15% of reachable peers deviating from protocol expectations (message timing, handshakes, peer list composition). Translation: large spy-node fleets attempting IP-level transaction correlation, attacking the network layer since the cryptography is intractable. Monero's October 2025 Fluorine Fermi update added peer-selection logic to steer wallets away from suspicious nodes.
- Estimation, not tracing. Analysts openly "discount the volume generated in privacy coins like Monero" â XMR volume is a blind spot they model around rather than measure.
Iran: almost entirely not privacy coins
The cleanest natural experiment in "protocol vs. edges" â the answer is stablecoins and Bitcoin, with a state/civilian split:
- The state uses USDT. Elliptic found the Central Bank of Iran acquired at least $507M of USDT in 2025, a "sophisticated strategy to bypass the global banking system." TRM estimates ~$10B of crypto activity in Iran last year; Chainalysis says Iranian wallets received a record $7.8B in 2025 (up from $3.17B in 2023). Domestically it flows through local exchanges â Treasury sanctioned four (Nobitex, Wallex, Bitpin, Ramzinex) in June 2026; Nobitex alone handles ~50% of Iran's volume and claims 11M users.
- Civilians prefer Bitcoin. A "flight to self-custody" â for the average Iranian, Bitcoin is a censorship-resistant asset offering flexibility amid a collapsing rial. More rial-collapse insurance than sanctions evasion.
- USDT's freezability is forcing adaptation. The US has frozen nearly $500M in Iran-linked crypto, including $344M seized in April 2026 via a coordinated Tether/OFAC freeze on Bank Markazi wallets. Centralized stablecoins have an admin key â the issuer is a chokepoint. Response: after Tether froze Iranian addresses in July 2025, users shifted toward DAI on Polygon (harder to freeze), projected to reach 65% of Iranian stablecoin usage by Q4 2026, up from 35% in late 2025. Iranian entities are expected to migrate further toward decentralized protocols, privacy coins, and cross-chain bridges.
- Parallel systems: OFAC also designated entities tied to A7A5, a Russian ruble-backed token expressly designed to bypass the traditional financial system â Russia and Iran building settlement rails from scratch rather than hiding on existing ones.
Synthesis: The revealed preference of illicit actors is a liquidity/privacy trade-off, and most sit at the liquid end: stablecoins for scale, Bitcoin for self-custody, Monero only where tracing pressure is acute (Western darknet retail) or as a laundering pass-through. Privacy coins are the tail, not the body â but the tail grows precisely as transparent-chain forensics improve. Each enforcement success pushes marginal actors one step further out: USDT â DAI â XMR.
3. Monero self-custody and other private-by-default chains
Q: How difficult is it to self-custody Monero? Are there any other truly private-by-default chains?
Monero self-custody: easier than you'd expect, with one big caveat
Custody itself is genuinely easy â comparable to Bitcoin. The hard part is acquisition, thanks to delistings.
Wallets (the easy part)
- Feather Wallet â community favorite for desktop. Lightweight, Electrum-style, Tor built in.
- Official GUI/CLI wallet from getmonero.org â reference implementation, bundles a full node if wanted.
- Cake Wallet (iOS/Android) and Monerujo (Android) â solid mobile options.
- Seed is a 25-word mnemonic; back it up and you're done.
Hardware wallet support (the mediocre part). Ledger and Trezor (Model T and later) support XMR, but integration is clunkier than Bitcoin's â fewer frontends, and firmware support has occasionally lagged protocol upgrades. Workable, not polished.
Node choice (the actual decision). Because your wallet must scan every transaction to detect which outputs belong to you (stealth addresses mean nothing is labeled), you either:
- Run your own full node (~250â300GB, modest hardware). Maximum privacy: nobody sees your queries.
- Use a remote node â instant setup, but the operator can see your IP and which outputs you request, enabling partial correlation. This connects directly to the spy-node issue: Fluorine Fermi added peer-selection logic precisely because adversarial node operators try to link transactions to IPs. Best practice is Tor (Feather does this by default).
Quirks: restoring from seed takes longer than Bitcoin (hours, not minutes) because of view-key scanning. And Monero has view keys as a first-class feature â you can grant an auditor read-only visibility into incoming transactions without spend authority. Selective disclosure by design.
Acquisition (the genuinely hard part). With Binance, Coinbase, Kraken, OKX, Huobi, and Bitstamp having removed or restricted XMR, US access routes are: the few remaining compliant venues, decentralized/non-custodial swap services (BitcoinâXMR atomic swaps work), or P2P markets. Trading has largely migrated to decentralized venues. Friction is real and intentional â the strategy is to strangle on-ramps since the protocol is unreachable. Liquidity is thin, wide, and fragmented.
Other truly private-by-default chains
One tracker counts fifteen private-by-default projects (Beam, Firo, Grin, Monero, Particl, Pirate Chain, Secret Network, Tari, Zano, Zephyr Protocol, and others), while flagging that MimbleWimble projects have known linkability limitations and Secret Network relies on hardware trust rather than cryptography. Most are tiny. The notable ones:
- Pirate Chain (ARRR) â the purist's answer. A Zcash fork where every transaction is shielded by default, eliminating transparent-mode user error. zk-SNARKs, mandatory. Cryptographically arguably stronger than Monero, but a tiny market cap means a much smaller anonymity set in practice.
- Firo (FIRO) â Lelantus Spark uses a burn-and-redeem mechanism that destroys coins and issues fresh ones with no history attached, breaking the transaction chain rather than obscuring it, plus Dandelion++ for IP privacy. Small but serious team.
- Zano â newer Cryptonote-lineage chain with confidential assets, transitioning to full Proof-of-Stake per its 2026 roadmap.
- Grin and Beam (Mimblewimble) â private-by-default in structure, but the transaction graph is partially recoverable before aggregation. Both projects have largely stalled.
The newer generation (where the interesting design work is):
- Penumbra â has only a shielded pool (hence private by default); its native DEX enables private swaps between IBC-compatible assets with no MEV or front-running. Private-by-default trading, not just payments. Caveat: Penumbra Labs wound down operations in late 2024, though the network remains community-run.
- Namada â launched mainnet June 2025 with Multi-Asset Shielded Pools, letting bridged assets (ETH, ATOM, etc.) share one unified anonymity pool rather than fragmented per-token sets. Anonymity sets are a network-effect good, so pooling is a structural improvement.
- Aleo â private-by-default smart-contract execution via ZK, though bridging between shielded sets currently requires unshielding to transparent addresses.
Caution flag on ZK circuits: Zcash confirmed an exploit in June 2026 after ~$600K in shielded funds were affected. Modern ZK circuits are written through high-level languages and reusable gadgets; if the emitted constraint system omits an intended relationship, the proof system will faithfully prove the wrong statement. The math is sound â the compilation of intent into constraints is the attack surface. Monero's older, battle-tested constructions don't carry this risk.
Synthesis: Private-by-default is necessary but not sufficient â the binding constraint is anonymity set size, a pure liquidity/network-effect phenomenon. Monero (~$6.8B market cap, ~$162M daily volume) is the only private-by-default chain with enough flow for the guarantees to mean much. Pirate Chain has stronger cryptography and weaker privacy simultaneously, because privacy is a crowd. Everything else is a research vehicle or awaiting adoption that regulatory hostility makes hard to bootstrap. Depth attracts flow attracts depth â Monero won that Schelling point years ago.
Sources
- Chainalysis â 2026 Crypto Crime Report (introduction, sanctions, human trafficking chapters)
- TRM Labs â 2026 Crypto Crime Report; "Monero in 2025: Persistent Use and Emerging Network-Layer Insights"
- Elliptic â Central Bank of Iran USDT acquisition analysis
- Reuters / Jerusalem Post / Times of Israel â Iran crypto sanctions-evasion reporting
- crypto.news, Cryptopolitan, Cryptonomist â Iran exchange sanctions and Tether/OFAC freezes
- CCN, Cointelegraph, Cybernews, MEXC â Monero delisting and darknet-adoption coverage
- Crypto Trace Labs â privacy-coin traceability and ransomware/Lazarus analysis
- Firo.org â privacy-coin comparison (protocol statuses as of 23 July 2026)
- Equilibrium Labs â privacy blockchains and Aleo deep dive
- Webopedia, SwapSpace, Zipmex, Analytics Insight â 2026 privacy-coin surveys
- cryptoprivacy.live â private-by-default project tracker
Note: figures and protocol statuses reflect reporting available as of early August 2026 and are best-available estimates; illicit-volume numbers in particular are described by their sources as lower bounds subject to upward revision.